CVE-2021-37471

HIGH
7.5CVSS v3
7.8CVSS v2
0.37% EPSS (exploit probability)
CWE

Description

Cradlepoint IBR900-600 devices running versions < 7.21.10 are vulnerable to a restricted shell escape sequence that provides an attacker the capability to simultaneously deny availability to the device's NetCloud Manager console, local console and SSH command-line.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected routers (1)

VendorModelMatched viaAffected versionsFixed inPatch?
Cradlepoint Cradlepoint IBR900 No

External references